AWS Certified Cloud Practitioner (CLF-C02)Security and ComplianceHard
A multinational company must ensure that customer data collected from users in the European Union is stored and processed only within EU-based AWS infrastructure to comply with data residency requirements. Which AWS concept primarily enables the company to meet this requirement?
- AEnabling AWS Shield Advanced in the EU-West-1 Region
- BConfiguring an Availability Zone-specific IAM policy
- CSelecting AWS Regions located within the EU when deploying resources
- DAWS Global Accelerator routing policies
Show answer & explanationAnswer & explanation
Correct answer: C. Selecting AWS Regions located within the EU when deploying resources
AWS gives customers control over where their data is stored by allowing them to choose specific AWS Regions; data does not automatically replicate to other Regions unless the customer configures it. Deploying resources in EU Regions (e.g., eu-west-1, eu-central-1) satisfies data residency requirements.
Why the other options are wrong
- A. Shield Advanced provides DDoS protection and has no bearing on data location
- B. IAM policies control permissions, not the physical location of stored data
- D. Global Accelerator optimizes network routing performance, not data residency control
Data Residency via Region Selection
AWS customers control data location by choosing specific AWS Regions to deploy resources; AWS does not move customer data across Regions without explicit action.
- Each AWS Region is a separate geographic area with multiple Availability Zones
- Data stored in a Region stays there unless the customer replicates or moves it
- Choosing appropriate Regions is key to meeting data residency/sovereignty laws
Memory trick: Pick your postcode — AWS keeps your data where you park it.